The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) by crashing an aircraft outside of the map.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openttd | Jul 30, 2024 | Dec 14, 2013 |
| Freebsd | — | Upgrade openttd | Dec 10, 2025 | Nov 28, 2013 |
| Gentoo Linux | — | Upgrade games-simulation/openttd. | Oct 30, 2017 | Dec 14, 2013 |
| Suse | — | Upgrade openttdUpgrade openttd-dedicatedUpgrade openttd-data | Jan 9, 2014 | Dec 14, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub